Proface GP-Pro ex d-Script Heap Buffer Overflow Remote Code Execution Vulnerability
Proface GP-Pro ex d-Script Heap Buffer Overflow Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Proface GP-Pro EX
Description:
Proface GP-Pro EX is a human-machine interface HMI software used on multiple platforms.
Proface GP-Pro EX has a security vulnerability in ParseAPI. dll processing D-Script data. Malformed files allow attackers to exploit this vulnerability to write D-Script data outside the heap buffer and execute arbitrary code in the context of the current process.
<* Source: Steven Seeley (seeleymagic@hotmail.com)
Link: http://www.zerodayinitiative.com/advisories/ZDI-16-006/
*>
Suggestion:
Vendor patch:
Proface
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.profaceamerica.com/en-US/content/gp-pro-ex-hmi-software
This article permanently updates the link address: